Before a single client document goes into an AI tool, a firm in England and Wales needs three things in place: a clear view of its SRA confidentiality duty, a UK GDPR position on where the data goes and how it is secured, and written vendor terms that match both. None of these is optional, and none of them is satisfied by a vendor's marketing page.
This is the checklist logic we run in readiness work with small firms. It is not a reason to avoid AI. It is the price of using it on client work.
1. The SRA duty does not care which tool you used
The SRA Code of Conduct for Solicitors requires you to keep the affairs of current and former clients confidential unless disclosure is required or permitted by law or the client consents. That duty sits on the firm and the individual solicitor, and it is not diluted because processing happened inside a third-party AI product. The SRA's own guidance on confidentiality of client information makes clear that outsourcing or technology arrangements do not move the duty.
Practical consequence: "the vendor said it is secure" is not a compliance position. The firm needs its own record of why using this tool, for this data, in this way is consistent with the duty.
2. UK GDPR: know where the data goes before it goes
Client files are personal data almost every time. Before use, the firm should be able to answer: where is the data processed and stored, is it used to train models, who are the sub-processors, how long is it retained, and what happens on deletion. The ICO treats security - including confidentiality - as a core processing principle, and expects organisational measures, not just technical ones. Systematic use of new technology on personal data is exactly the territory where a data protection impact assessment belongs, and the ICO's DPIA guidance sets out when one is required.
3. Read the vendor terms against your duties, not against their homepage
The questions that matter are contractual: no training on your data without consent, retention and deletion terms you can evidence, breach notification commitments, sub-processor transparency, and UK/EU processing options where you need them. Our vendor data security questions page lists the specific questions to put to suppliers, and the vendor terms index tracks what the major tools actually say.
4. Supervision is part of confidentiality too
The Law Society's generative AI guidance treats output checking and staff supervision as part of safe use, not an optional extra. A firm that cannot say who checks AI output before it reaches a client has a confidentiality problem even if the vendor terms are perfect - because errors and fabrications in client documents are themselves a failure of the service the client is paying for.
5. Write the decision down
Whatever you decide - approved tool, approved use cases, banned uses, redaction rules - record it. A one-page position the whole firm can read beats a policy nobody opened. If you want that position built properly, our readiness work produces it as part of the audit, and the Workflow Value Workshop scopes where AI should and should not touch your client work at all.
Evidence ledger
| Claim | Source |
|---|---|
| Solicitors must keep current and former clients' affairs confidential unless law or consent permits disclosure | SRA Code of Conduct for Solicitors, para 6.3 - https://www.sra.org.uk/solicitors/standards-regulations/code-conduct-solicitors/ |
| Confidentiality duty is not moved by outsourcing or technology arrangements | SRA, Confidentiality of client information - https://www.sra.org.uk/solicitors/guidance/confidentiality-client-information/ |
| Security/confidentiality is a core UK GDPR principle requiring organisational as well as technical measures | ICO, Principle (f) integrity and confidentiality - https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-protection-principles/a-guide-to-the-data-protection-principles/integrity-and-confidentiality-security/ |
| New-technology processing of personal data is DPIA territory; ICO guidance sets the thresholds | ICO, DPIAs - https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/data-protection-impact-assessments-dpias/ |
| ICO expectations on organisational security measures | ICO, A guide to data security - https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/security/a-guide-to-data-security/ |
| Supervision and output checking are part of safe generative AI use | Law Society, Generative AI: the essentials - https://www.lawsociety.org.uk/topics/ai-and-lawtech/generative-ai-the-essentials |
Weak-claim flags: the five-part structure is our framing of the duties, not a regulator's checklist; the copy presents it as such. Internal links: legal-ai-vendor-data-security-questions, legal-ai-vendor-terms-index, /readiness/, /workshop/. No prices stated for audit or sprint work; Workshop referenced by name and link only.